Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Extra entries in the Windows Hosts file do not, by themselves, prove that your PC has malware. Antivirus, ad-blocking, privacy, VPN, developer, and business-management tools can all affect local name resolution. But entries that redirect important websites to unfamiliar addresses—or keep returning after removal—deserve investigation.

In the case behind this topic, a malware-removal helper judged the computer clean and attributed its additional entries to Bitdefender. That was a case-specific assessment, not a rule about every Bitdefender installation. The safe approach is to preserve the file, identify what each entry does, and scan or reset only when the evidence supports it.

What the Hosts file does

Windows checks the Hosts file when resolving a hostname to an IP address. An entry there can take precedence over ordinary DNS lookup: it can send a domain to a specified address or block it by mapping it to a local address. The file is plain text, has no .txt extension, and normally lives at C:WindowsSystem32driversetchosts (or %WinDir%System32driversetchosts). Microsoft explains the file and its default contents in its Hosts-file reset instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A typical active line has an IP address followed by one or more hostnames, for example:

127.0.0.1 localhost
::1 localhost

Lines beginning with # are comments. Some files contain explanatory comments or many mappings; neither comments nor length alone establish that a file is malicious. A 127.0.0.1 or 0.0.0.0 destination is also not automatically suspicious: blocking lists and local filtering tools commonly use those addresses.

Why legitimate software may add entries

Security products may use mappings to block known unwanted destinations or provide protection. Ad and tracking blockers can maintain extensive lists. VPN or privacy software can change how network names are resolved, though having a VPN installed does not prove that it wrote a particular Hosts entry. Developers and administrators may add local or staging-site overrides, and entries can remain after an old program is uninstalled. Corporate security agents and parental-control or DNS-filtering products may also manage settings.

In the specific BleepingComputer support case, the user had Bitdefender and ExpressVPN in the picture; the malware-removal helper concluded that the computer was clean and that the entries were related to Bitdefender. That conclusion was based on the case’s logs and review, not an independent forensic certification. The presence of a product on your PC is a useful clue, not proof of authorship. Compare the entries with the product’s settings or documentation, its logs, installation timing, and any available file-change evidence.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which entries deserve closer attention?

Investigate entries more carefully if they map Microsoft, Windows Update, antivirus, banking, payment, email, or search domains to unfamiliar public IP addresses; contain misspelled or lookalike domain names; or send many unrelated domains to one unfamiliar destination. Concern rises if those changes coincide with browser redirects, certificate warnings, security tools that will not open, or unknown services, scheduled tasks, startup items, or recently created programs.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Microsoft documents a Hosts-file hijack detection category involving suspicious changes to protected domains. That is a reason to examine the specific mapping, not evidence that every custom entry is malicious. See Microsoft Security Intelligence’s description.

Also note whether entries reappear after a reset. Recurrence suggests that some program, policy, or other process is writing the file again; it does not identify which one by itself. Keep in mind that similar connectivity symptoms can come from a proxy, router, VPN, browser secure-DNS setting, or DNS provider without any Hosts-file change.

Inspect and preserve the file before changing it

  1. Open Notepad as administrator. One way is to search for Notepad, choose Run as administrator, then approve the prompt.
  2. In Notepad, choose File → Open and browse to C:WindowsSystem32driversetc. Change the file filter from Text Documents (*.txt) to All Files, then open hosts. Alternatively, from an elevated Command Prompt, run notepad %windir%System32driversetchosts.
  3. Before editing, preserve a copy. From Command Prompt, run:
    copy "%windir%System32driversetchosts" "%userprofile%Desktophosts.backup"
    Or copy the file in File Explorer and name the copy hosts.backup.txt. Keep the original untouched while you investigate.
  4. Record the entries and IPs, the file’s timestamps, when symptoms began, and which antivirus, VPN, ad-blocking, privacy, or business-security tools are installed. Note whether the file changes again.

If the file is missing, inaccessible, or has an unexpected extension, preserve the surrounding directory and seek qualified help before overwriting it. If you use Microsoft PowerToys, its Hosts File Editor offers filtering and backup features; saving changes requires administrator access. It helps edit the file but does not determine whether a mapping is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scan and correlate instead of guessing

Start with the security software already installed: confirm real-time protection is enabled and current, then run a full scan. If symptoms or suspicious mappings persist, use a reputable second-opinion scanner obtained from its vendor’s official site. Check whether Windows Update and security-vendor websites are reachable, and review browser extensions, startup apps, scheduled tasks, services, and proxy settings. Compare the Hosts-file timestamps with software installs or updates, and consult relevant vendor logs or support materials.

Rank #3

Interpret scan reports carefully. In the cited case, Sophos Scan & Clean reported zero threats and 68 traces; the helper treated the report as clean. “Traces” or remnants are not automatically 68 active infections. A clean scan is useful evidence, but it cannot establish that every historical file change was benign.

Do not run a fixlist from an unrelated forum post or treat Farbar Recovery Scan Tool (FRST) as a routine cleanup utility. The original case used FRST under a trained helper’s direction, who cautioned the user not to run additional tools or steps independently. Diagnostic logs and remediation instructions depend on the machine; if a specialist is reviewing yours, follow that person’s directions rather than adding fixes in parallel.

Reset the file only if you intend to remove its custom mappings

If you have preserved the file, do not need its deliberate overrides, and no specialist needs the original for review, restore Microsoft’s default Hosts-file contents. Use Microsoft’s official reset procedure for your Windows version. In brief: open Notepad as administrator, replace the contents with the appropriate default text, and save as hosts—not hosts.txt—in %WinDir%System32driversetc. In the Save As dialog, select All Files. If replacing the file is blocked, Microsoft’s procedure may require renaming the old file to Hosts.old before saving the new one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Resetting removes custom name-resolution mappings; it does not remove malware, a scheduled task, a malicious browser extension, or another process that may have created them. After a reset, restart affected applications, test the relevant sites, and optionally clear the DNS client cache in an elevated Command Prompt:

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
ipconfig /flushdns

If the entries return, focus on identifying the writer or policy that recreated them instead of repeatedly deleting the file. A reset can also break legitimate development overrides or managed configurations, so check before replacing a file on a work or school PC.

When to stop and ask for specialist help

Escalate if entries return, security websites remain inaccessible, protection is disabled or tampered with, traffic keeps redirecting, or you find unknown services, scheduled tasks, or executables. Seek prompt help if there are signs of ransomware or credential theft, and use a separate trusted device to contact financial providers if accounts may be exposed. For a review, provide the untouched Hosts file, scan logs, relevant timestamps, and a clear symptom timeline. Redact usernames, email addresses, license keys, personal IPs, and other sensitive information before posting logs publicly.

Avoid downloading unknown “Hosts cleaners,” disabling antivirus or firewall protection to silence a warning, or installing multiple real-time antivirus products at once. Do not restore a Hosts file from an untrusted download. If a security product flags a customized file, investigate the specific detection and its source rather than applying a blanket exclusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not assume the Hosts file explains a slow PC

The Hosts file is a text mapping list; by itself it is unlikely to explain slow booting, high disk activity, or general sluggishness. Treat file integrity, name-resolution problems, antivirus or VPN behavior, startup performance, and malware evidence as separate questions. A failed security-service start, heavy startup workload, or aging storage may merit their own investigation.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

That distinction mattered in the support case: Bitdefender services and a failed service start appeared in the discussion, and the helper suggested uninstalling Bitdefender as a troubleshooting step if it seemed to contribute to performance problems. Older storage hardware and other running processes were also considered separately. Those observations did not change the case’s Hosts-file conclusion, and they should not be treated as a diagnosis for other PCs.

What the case does—and does not—show

The BleepingComputer thread began in January 2025 on a Windows 10 Home 22H2 system at the time of its posted scan. The helper concluded that the machine was clean and attributed the extra Hosts entries to Bitdefender; the later Sophos report listed zero threats and 68 traces. These are historical, case-specific findings. They show why an unfamiliar entry warrants context and careful review—not why every modified Hosts file is safe, or why every addition means a Trojan.

For the original discussion, see the case thread and its follow-up page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$309.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$247.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.